Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Use Google’s experimental, read-only Analytics MCP server locally: enable the Google Analytics Admin API and Data API in a Google Cloud project, authenticate with Application Default Credentials (ADC) for a Google user who can access the GA4 property, then register the server in Gemini CLI or Claude Code. The server can answer reporting and property questions, but it cannot change Analytics settings. Google’s current guide describes the server as a way to connect Analytics data to an LLM such as Gemini (Google for Developers, updated September 16, 2025).
What the Google Analytics MCP connection does
Model Context Protocol (MCP) gives an AI client a standard way to call tools. Google’s official Analytics MCP server runs as a local process and uses the Google Analytics Admin API and Google Analytics Data API. After you connect it, an approved client can retrieve account summaries, property details, Google Ads links, standard reports, funnel reports, custom dimensions and metrics, and realtime reports.
Typical prompts include “How many users arrived yesterday?”, “Which products sold best?” or “What are the most popular events in my property in the last 180 days?” The server is read-only: it cannot edit your Google Analytics configuration or settings.
Requirements and access model
- A Google Cloud project where you can enable APIs and manage credentials.
- Access to the GA4 account or property you want to query. Google credentials without Analytics permissions will authenticate but return no usable property data.
- Python and
pipxfor the documented local runner. - Gemini CLI, Gemini Code Assist, or Claude Code as your MCP client.
The local setup uses Application Default Credentials (ADC) and the read-only scope https://www.googleapis.com/auth/analytics.readonly. For a hosted, multi-user design, use a carefully designed OAuth or workload identity flow instead of copying one developer’s local credential file.
#1 Best Overall
Step 1: Create or choose a Google Cloud project
- Open the Google Cloud project selector and choose an existing project or create a new one.
- Note the project ID. You will supply it as
GOOGLE_PROJECT_ID. - Ensure the Google account you will authenticate has permission to enable APIs and create or use credentials in that project.
Step 2: Enable both Analytics APIs
In Google Cloud Console, open APIs & Services → Library for the selected project and enable:
- Google Analytics Admin API (account, property, links, dimensions and metrics metadata).
- Google Analytics Data API (reports, funnels and realtime data).
Enabling only one is a common cause of partial failures: administrative discovery may work while reports fail, or the reverse.
Step 3: Create ADC credentials with the Analytics scope
Install the Google Cloud CLI if it is not already installed, then run:
gcloud auth application-default login
--scopes=https://www.googleapis.com/auth/analytics.readonly
Complete the browser sign-in with the Google user who can access the target GA4 account or property. The command prints the ADC JSON location. Keep that path private; do not commit the file or place it in a public workspace.
Set the environment variables in the shell that will launch your MCP client. Replace the path and project ID with your values:
Rank #2
- The Google Workspace Bible: [14 in 1] The Ultimate All in One Guide from Beginner to Advanced Including Gmail, Drive, Docs, Sheets, and Every Other App from the Suite
- ABIS BOOK
export GOOGLE_APPLICATION_CREDENTIALS="/secure/path/application_default_credentials.json"
export GOOGLE_PROJECT_ID="your-google-cloud-project-id"
On Windows PowerShell, use $env:GOOGLE_APPLICATION_CREDENTIALS="C:secureapplication_default_credentials.json" and $env:GOOGLE_PROJECT_ID="your-project-id". Re-authenticate if the existing ADC token was created without the Analytics read-only scope.
Step 4: Install and run the official server
Install pipx using your operating system’s package instructions, then verify it is available:
pipx --version
The repository’s documented runner is:
pipx run analytics-mcp
pipx run downloads and runs the package in an isolated environment. For repeatable deployments, review the project’s pinned-version guidance and keep the experimental server updated deliberately rather than silently changing versions in production.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Step 5: Configure Gemini
Edit ~/.gemini/settings.json and add an analytics-mcp entry under mcpServers. Keep the JSON structure intact if you already have other servers:
{
"mcpServers": {
"analytics-mcp": {
"command": "pipx",
"args": ["run", "analytics-mcp"],
"env": {
"GOOGLE_APPLICATION_CREDENTIALS": "/secure/path/application_default_credentials.json",
"GOOGLE_PROJECT_ID": "your-google-cloud-project-id"
}
}
}
}
Restart Gemini CLI or Gemini Code Assist. Type /mcp; analytics-mcp should be listed. If it is missing, the client usually rejected the JSON, cannot find pipx, or did not inherit the environment variables.
Rank #3
Step 6: Configure Claude Code
Claude Code can register the same local process with its user scope. Run the documented command (substitute your credential path and project ID):
claude mcp add analytics-mcp --scope user
-e GOOGLE_APPLICATION_CREDENTIALS=/secure/path/application_default_credentials.json
-e GOOGLE_PROJECT_ID=your-google-cloud-project-id
-- pipx run analytics-mcp
Restart or reload Claude Code, inspect its MCP server list, and confirm that the process starts without an authentication error.
Free tools Windows power users keep installed
One-click scans. No signup required.
Step 7: Verify with a read-only query
- First ask for property details, such as “List the Analytics properties available to my authenticated account.” This tests discovery and permissions without relying on a particular report date.
- Then ask for a bounded report: “What were the most popular events in my Google Analytics property during the last 180 days? Include event count and date range.”
- Check the property name, property ID, date range and timezone in the response before using the result in a decision.
Natural-language answers are only as reliable as the selected property and metric definitions. Ask the model to state the dimensions, metrics and date range it used when a result matters.
Authentication options beyond local ADC
Google documents several authentication patterns for Google and Google Cloud remote MCP servers:
| Method | Where it fits | Important boundary |
|---|---|---|
| Application Default Credentials | Local development and a single operator | The signed-in user must have Analytics access; protect the ADC file. |
| OAuth 2.0 client ID and secret | Interactive or multi-user applications | Store client secrets securely and request only required scopes. |
| Authorization header | A remote client sending an OAuth bearer token | The token’s principal still needs access to the Analytics resource. |
| API key | Only services that do not require a principal | An API key does not replace Analytics user or resource permissions. |
Google says remote Google MCP servers do not support Dynamic Client Registration or OAuth Client ID Metadata Documents. A Google Cloud integration that applies IAM may also require the predefined MCP Tool User role (roles/mcp.toolUser), which contains mcp.tools.call. That role does not grant GA4 data access by itself; the underlying Analytics permissions remain necessary.
Rank #4
Security and operational boundaries
- Least privilege: use the Analytics read-only scope and grant the user or workload only the accounts and properties it needs.
- Secret handling: keep ADC JSON, OAuth secrets and bearer tokens out of source control, logs and client prompts.
- Property selection: in organizations with many properties, require the model or calling application to identify the property ID explicitly.
- Read-only expectations: the official server cannot create events, alter retention, edit audiences or change any other Analytics configuration.
- Experimental status: the official repository labels the project experimental. Treat upgrades, tool names and production support expectations accordingly.
Troubleshooting: symptoms, causes and fixes
“API has not been used” or permission-denied errors
Confirm that both the Admin API and Data API are enabled in the project named by GOOGLE_PROJECT_ID. Make sure the MCP process is using that same project, not a different shell’s default project.
The server starts but shows no GA4 property
Check that the Google account used by gcloud auth application-default login has access to the target Analytics account or property. Being an editor of the Cloud project does not automatically grant Analytics access.
Invalid credentials or file-not-found
Run gcloud auth application-default login again, copy the exact ADC path it reports, and verify GOOGLE_APPLICATION_CREDENTIALS points to that file. Avoid relative paths when Gemini or Claude launches from a different working directory.
Insufficient authentication scope
Recreate ADC with https://www.googleapis.com/auth/analytics.readonly. Existing tokens may continue to lack the scope until you authenticate again.
Gemini does not list the server
Validate the JSON under mcpServers, confirm the command is exactly pipx, and confirm the arguments are run and analytics-mcp. Restart the client and inspect /mcp.
Claude Code cannot launch it
Run pipx run analytics-mcp directly in the same shell to expose installation or Python errors, then repeat the claude mcp add command with absolute credential paths. Ensure environment variables are attached to the MCP entry, not merely set in another terminal.
Assuming local settings apply to a remote endpoint
A Google-hosted remote MCP server has separate authentication and IAM rules. Do not copy the local pipx configuration to a remote URL; follow that endpoint’s documented OAuth, bearer-token or API-key method, and remember Google’s restriction on Dynamic Client Registration.
Or skip the browser setup
If your broader workflow also needs clean website screenshots for reports or AI tools, ScreenshotNeo is a separate screenshot API and MCP server; it is not a replacement for Google Analytics access. One GET request returns PNG, JPEG, WebP or PDF, while its MCP tools let Claude, Cursor and other MCP clients call take_screenshot, get_page_info and capture_pdf.
Use the API with the documented call below (see the ScreenshotNeo documentation):
Recommended Free Tools
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
ScreenshotNeo accepts cookie and consent banners as a visitor and removes more than 60 known consent platforms, newsletter popups and chat widgets before capture. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed; response headers identify the page verdict and billing status. The Free plan includes 1,000 screenshots per month with no card, and paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.
FAQ
Can the official server change GA4 settings?
No. Google documents it as read-only for Analytics requests.
Does Cloud project access equal GA4 property access?
No. The authenticated identity needs permission on the Analytics account or property as well as any required Cloud permissions.
Can I use this with a remote MCP client?
Yes, but remote Google MCP authentication is a separate design using documented OAuth, bearer-token or, where applicable, API-key rules. The local ADC recipe is not a universal remote configuration.
Is the official server production-ready?
The official repository labels it experimental, so evaluate version changes, operational controls and support needs before relying on it for critical workflows.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

